Members Login

Rss Feeds

Get our latest content via RSS feeds.

Report a Vulnerability

Report a vulnerability or exploit that you have found to SecuMania.
vul[at]SecuMania.org

 

Latest Comments

I cant say I feel sorry for him, stupid spammer got what he deserved. We all know how it feels to op...
thanks smiley
hi webmaster,plz help me to find any information about account harvesting and traversal path attack ...
Hello Webmasters My name is Nikolai. I am making an organization for the protection internet users f...
good job you are the best . mgharba talmout :d
Hello, The reported problem has been fixed. Regards, Catalina Danila Online Rent Customer Supp...
Not Vulnerable: Luis Wang netOffice Dwins 1.3.1 visit website http://netofficedwins .sourceforge.ne...
Current version of script corrected. Security patch available to registered users in the user foru...
But i think to protect the password is not needed because it's not used in the SQL-Execute statement...
you may find that your hotfix doesnt stop the password field from having SQL injected into it. This ...

Who's Online

Total: 23
Members: 0 / Guests: 23
No members online

Packet Storm

Visits today: 761
Visits yesterday: 943
Visits month: 10681
Visits total: 468060
Pages total: 8769752
Cisco 7940 SIP Phone INVITE Message Remote Denial of Service Vulnerability Print E-mail
0
Wednesday, 05 December 2007
Cisco 7940 SIP Phone INVITE Message Remote Denial of Service Vulnerability
Class: Failure to Handle Exceptional Conditions
CVE: CVE-2007-5583
Remote: Yes
Local: No
Published: Dec 05 2007 12:00AM
Updated: Dec 11 2007 03:52AM
Credit:
Humberto J. Abdelnur, Radu State, and Olivier Festor are credited with the discovery of this vulnerability.
Vulnerable:
Cisco IP Phone 7940
Not Vulnerable:
Description:
Cisco 7940 SIP phones are prone to a denial-of-service vulnerability because the device fails to handle specially crafted SIP INVITE messages.

Exploiting this issue allows remote attackers to cause the device to fail to respond to further call requests and to potentially crash, denying service to legitimate users.

This issue affects version P0S3-08-7-00 of Cisco 7940 SIP phones; other versions may also be affected.
Exploit:
To exploit this issue, attackers may use readily available network utilities.

The following exploit code is available:
Solution:
Currently SecuMania is not aware of any solution for this issue.
If you are aware of more recent information, please mail us at: vul[at]SecuMania.org.
References:
Source:
Hits: 84
Comments (0)add
Write comment
quote
bold
italicize
underline
strike
url
image
quote
quote
smile
wink
laugh
grin
angry
sad
shocked
cool
tongue
kiss
cry
smaller | bigger

security image
Write the displayed characters


busy
 
< Prev   Next >

Polls

How do you rate the SecuMania Security Portal?
 

web design company
Warning: file_put_contents() failed to open stream: Permission denied in /home/inowweb/public_html/secumania.org/index.php on line 741